CVE-2021-42260
published 2021-10-11CVE-2021-42260: TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.28%
87.2th percentile
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tinyxml | < tinyxml 2.6.2-6 (bookworm) | tinyxml 2.6.2-6 (bookworm) |
| tinyxml_project | tinyxml | — | — |
| tinyxml_project | tinyxml | — | — |
| tinyxml_project | tinyxml | >= 0 < 2.6.2-4+deb11u1 | 2.6.2-4+deb11u1 |
| tinyxml_project | tinyxml | >= 0 < 2.6.2-6 | 2.6.2-6 |
| tinyxml_project | tinyxml | >= 0 < 2.6.2-6 | 2.6.2-6 |
| tinyxml_project | tinyxml | >= 0 < 2.6.2-6 | 2.6.2-6 |
| tinyxml_project | tinyxml | 2.3.2 – 2.6.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
TinyXML vulnerability
vendor_ubuntu·2023-12-07
CVE-2021-42260 TinyXML vulnerability
Title: TinyXML vulnerability
Summary: TinyXML could be made to crash if it opened a specially crafted
file.
Wang Zhong discovered that TinyXML incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-42260: tinyxml - TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxml...
vendor_debian·2021·CVSS 7.5
CVE-2021-42260 [HIGH] CVE-2021-42260: tinyxml - TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxml...
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
Scope: local
bookworm: resolved (fixed in 2.6.2-6)
bullseye: resolved (fixed in 2.6.2-4+deb11u1)
forky: resolved (fixed in 2.6.2-6)
sid: resolved (fixed in 2.6.2-6)
trixie: resolved (fixed in 2.6.2-6)
GHSA
GHSA-x43j-m68c-2qxf: TinyXML through 2
ghsa_unreviewed·2022-05-24
CVE-2021-42260 [HIGH] CWE-835 GHSA-x43j-m68c-2qxf: TinyXML through 2
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
OSV
CVE-2021-42260: TinyXML through 2
osv·2021-10-11·CVSS 7.5
CVE-2021-42260 [HIGH] CVE-2021-42260: TinyXML through 2
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QCR5PIOBGDIDS6SYRESTMDJSEDFSCOE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HOMBSHRIW5Q34SQSXYURYAOYDZD2NQF6/https://sourceforge.net/p/tinyxml/bugs/141/https://lists.debian.org/debian-lts-announce/2022/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00041.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4QCR5PIOBGDIDS6SYRESTMDJSEDFSCOE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HOMBSHRIW5Q34SQSXYURYAOYDZD2NQF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/4QCR5PIOBGDIDS6SYRESTMDJSEDFSCOE/https://lists.fedoraproject.org/archives/list/[email protected]/message/HOMBSHRIW5Q34SQSXYURYAOYDZD2NQF6/https://sourceforge.net/p/tinyxml/bugs/141/
2021-10-11
Published